The 48-hour period from July 1-2, 2026 reveals a critical convergence of supply chain threats, infrastructure vulnerabilities, and credential-harvesting campaigns. Most notably, Google Chrome released patches for 382 security vulnerabilities including 15 critical-severity flaws, while a massive FortiBleed credential theft campaign has been definitively linked to INC and Lynx ransomware operations—indicating stolen Fortinet credentials are being weaponized for network intrusions. The period also saw the compromise of DHS's Homeland Security Information Network (HSIN), a sensitive federal information-sharing platform, and an 81-million-attempt password-spraying campaign targeting Microsoft 365 environments.
Ransomware activity remained aggressive with 26 new victim disclosures, led by high-profile targets including Fluke Corporation (21+ million Salesforce records) and Ingram Content Group. Multiple critical vulnerabilities emerged in widely-deployed technologies including Oracle E-Business Suite (900+ exposed instances), Adobe ColdFusion, and Rancher/Fleet container management platforms. Emerging attack techniques include AI-driven "Phantom Squatting" (LLM-hallucinated domains registered for malicious use), adaptive phishing campaigns that fingerprint victim devices to deliver OS-specific payloads, and ClickFix social engineering dominating malware delivery. The ChocoPoC campaign demonstrates continued targeting of security researchers through trojanized proof-of-concept exploits.
Google Chrome, Oracle E-Business Suite, Adobe ColdFusion, and multiple container/authentication platforms disclosed critical vulnerabilities with active exploitation or high exposure risk.
Google released Chrome update fixing 382 security vulnerabilities, 15 rated critical severity. Multiple sandbox escape vulnerabilities in Dawn, ANGLE, Skia, and V8 components. Immediate patching required for all Chrome deployments.
Critical use-after-free in ANGLE component allows remote attacker to perform sandbox escape via crafted HTML. CVSS 9.6. Part of mass Chrome update addressing rendering engine vulnerabilities.
Critical out-of-bounds read and write vulnerability in Dawn (WebGPU implementation) enables sandbox escape. CVSS 9.6. Affects all Chrome versions prior to 150.0.7871.46.
More than 900 Oracle E-Business Suite (EBS) instances discovered exposed online amid ongoing attacks exploiting critical security flaw. Organizations running EBS face immediate compromise risk.
Adobe released patches for seven maximum-severity vulnerabilities in ColdFusion web application development platform and Campaign Classic marketing automation platform. Both platforms widely deployed in enterprise environments.
Critical privilege escalation vulnerability in Rancher container management platform allows Project Owner role to escalate to Host-level access. CVSS 9.4. Affects widely-deployed Kubernetes management infrastructure.
Critical vulnerability in Rancher Fleet allows cross-namespace secret disclosure via unvalidated valuesFrom references in Helm Deployer. CVSS 9.9. Enables unauthorized access to sensitive Kubernetes secrets.
Critical command injection vulnerability in Rancher through unsanitized YAML parameter. CVSS 9.4. Allows authenticated attackers to execute arbitrary commands on Kubernetes management infrastructure.
Critical cache-poisoning XSS vulnerability in Ghost frontend CMS via x-ghost-preview header manipulation. CVSS 9.6. Affects widely-deployed blogging platform enabling stored XSS attacks.
FortiBleed credential theft campaign linked to ransomware operations, aggressive password spraying against M365, and 26 new ransomware victim disclosures including major enterprises.
Massive FortiBleed credential theft campaign definitively linked to INC and Lynx ransomware operations. Stolen Fortinet credentials being weaponized for network intrusions. Organizations with Fortinet deployments face elevated ransomware risk from compromised credentials.
Department of Homeland Security investigating cyberattack compromising Homeland Security Information Network (HSIN), sensitive information-sharing platform used by federal, state, local, and private-sector partners. Breach potentially exposes sensitive law enforcement and critical infrastructure information.
Aggressive password-spraying campaign targeting Microsoft 365 environments generated over 81 million login attempts during two-week period. Indicates large-scale credential compromise operation targeting enterprise cloud environments.
19-year-old suspect in Scattered Spider hacking incidents extradited to US. Complaint accuses defendant of participating in breach of luxury-jewelry retailer in 2025. Scattered Spider known for social engineering and SIM-swapping attacks targeting high-value enterprises.
ChocoPoC campaign targets security researchers, ClickFix technique dominates malware delivery, and fake browser extensions deployed for credential theft.
Multiple weaponized proof-of-concept exploits on GitHub delivering Python-based RAT named ChocoPoC. Campaign specifically targets cybersecurity researchers, capable of executing commands and stealing sensitive data. Demonstrates continued threat to security research community.
ClickFix social engineering technique no longer exception but now the rule for malware attacks. Highly effective method tricks users into executing malicious commands. Researchers report widespread adoption across threat actor groups.
Malicious Chrome extension masquerading as Perplexity AI secretly monitored user searches. Extension named 'Search for perplexity ai' requires manual removal. Demonstrates supply chain risk from malicious browser extensions targeting AI tool users.
Multiple VBS malware payloads hosted at jim-s.com disguised as Zoom meeting downloads. Campaign using social engineering themed around video conferencing to deliver Visual Basic Script malware.
Multiple Mozi botnet malware download URLs detected targeting MIPS and ARM architectures. Despite reported takedown efforts, Mozi infrastructure continues distributing IoT malware for botnet recruitment.
AI-driven supply chain threats including LLM hallucination exploitation, adaptive phishing campaigns, and AI agent manipulation techniques.
LLMs consistently hallucinate web domains for legitimate brands that attackers can register for malicious activity. Difficult-to-detect attack vector exploits AI tendency to generate plausible but non-existent URLs. Organizations face brand impersonation and supply chain compromise risk.
Attackers fingerprinting victims through user-agent data to deliver OS-specific payloads, increasing compromise rates and campaign profitability. Phishing pages dynamically adapt content based on victim's device, OS, and browser for maximum effectiveness.
Researchers demonstrated BioShocking proof-of-concept that tricks AI agents by gamifying outcomes. Warning to AI vendors about manipulation vulnerabilities in autonomous agent systems. As AI agents gain enterprise deployment, adversarial manipulation becomes critical concern.
AI assistants like ChatGPT produced graphic violent images that shocked researchers despite supposed guardrails. Demonstrates inadequacy of current content filtering mechanisms and potential for AI misuse in social engineering attacks.
26 new ransomware victim disclosures with notable targets including Fluke Corporation (21M+ Salesforce records), Ingram Content Group, and multiple healthcare and manufacturing organizations.
Over 21 million Salesforce records containing PII compromised from test and measurement equipment manufacturer Fluke Corporation. ShinyHunters ransomware group claims 100GB+ dataset. Company failed to reach agreement with threat actors despite multiple negotiation opportunities.
Book distribution and publishing services giant Ingram Content Group data leaked by ShinyHunters ransomware group. Company failed to reach agreement despite extended negotiations. One of largest book distributors in North America.
Horizon Eye Care optometric clinic group compromised by INC ransomware. Network of independent eye care clinics across North America. Patient health information potentially exposed.
Luxury Refinery Hotel in New York City near Bryant Park hit by Akira ransomware. 197-room boutique hotel with guest data potentially compromised including reservations and payment information.
Kubota North America Corporation disclosed hackers had access to network systems for more than one month earlier in 2026. Agricultural and construction equipment manufacturer investigating extent of data exposure during extended dwell time.
Krybit ransomware group disclosed 9 new victims including Taiwanese electronics manufacturers (JAWS, AeroVision Avionics), Guatemalan logistics firm, Spanish IT consulting, and healthcare organization. Demonstrates focus on Asian and European manufacturing supply chains.
Aflac Tokyo, brewer Sapporo, manufacturer Nidec, and telecom KDDI among major Japanese companies recently notifying public about data breaches. Indicates widespread compromise campaign targeting Japanese corporate infrastructure.
FTC action against Amazon, US export control changes for AI cybersecurity models.
FTC fined Amazon $2.25 million civil penalty for blocking identity theft victims' access to transaction records. Enforcement action addresses impediments to consumer fraud investigations and identity theft recovery.
US government lifted export controls on certain Anthropic frontier AI models for cybersecurity applications after company reached series of agreements with government. Signals evolving policy framework for AI security tool distribution.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.